RSS

Tag Archives: 212.52.84.102

“Precious Johnson”

ONLINE DATING SCAM / 419 SCAM

Precious Johnson also sends out spam mail under the name Precious Weah and Blessing Bouma

Subject: Hello
From: Precious Johnson precious_189_1p

Hello
My name is precious Johnson
i saw your profile today(penpal-net.info) and became interested in you,i will
also like to know you the more,and i want you to send an email to my email
address so i can give you my picture for you to know whom i am.Here is my email
address (preciousjohnson970@yahoo.com)
I believe we can move from here!I am waiting for your mail to my email address
above.
precious
(Remeber the distance or colour does not matter but love matters alot in life)
please contact me here preciousjohnson970@yahoo.com

Return-Path: precious_189_1p88888@libero.it
Received-SPF: pass (domain of libero.it designates 212.52.84.102 as permitted sender)
X-Originating-IP: [212.52.84.102]
Authentication-Results: mta1125.mail.bf1.yahoo.com
Received: from 127.0.0.1 (EHLO outrelay02.libero.it) (212.52.84.102)
by mta1125.mail.bf1.yahoo.com with SMTP; Thu, 20 Jun 2013 23:23:55 -0700
X-CTCH-Spam: Yes
X-CTCH-RefID: str=0001.0A0C0204.51C3F179.002A,ss=1,re=0.000,fgs=0
X-libjamoibt: 1587
Received: from wmail44 (172.31.0.234) by outrelay02.libero.it (8.5.140.03)
id 51589FB60B10153D; Fri, 21 Jun 2013 08:23:53 +0200
Message-ID: <22915950.14955331371795833059.JavaMail.root@wmail44>
From: precious_189_1p <precious_189_1p88888@libero.it>
Reply-To: preciousjohnson970@yahoo.com
Subject: Hello
X-SenderIP: 78.43.46.42
X-libjamv: VDPS5Cfg5x4=
X-libjamsun: iRJlE1l+Vgn9o2jbtAPkptgMKKhmb5lWTBrEynAjbPA=

 
Leave a comment

Posted by on 07/03/2013 in Romance Scam

 

Tags: , , , , , , , , , ,

“Atia Yasie”

ONLINE DATING SCAM / 419 SCAMMER

animated arrow down2

Subject: Hello Dear
From: atia yasie atiayasi5@libero.it
Reply-Address: atiayasie@yahoo.fr

Hello Dear,

I’m YASIE, by name.i was browsing looking for honest partner, then i felt
to drop this few lines. to see if you could be interested establishing a
nice relationship with me , I’m a loving lady, very romantic, i’m seeking
for my true love,I want to end my loneliness. True love is hidden in every
heart and it bonds for lifetime. For more details about me, kindly get
back to me to my private email address at(atiayasie@yahoo.fr). Waiting
earnestly for your reply.
best regards.
have a nice day.
YASIE

Return-Path: <atiayasi5@libero.it>
Received-SPF: pass (domain of libero.it designates 212.52.84.102 as permitted sender)
X-Originating-IP: [212.52.84.102]
Authentication-Results: mta1323.mail.ne1.yahoo.com
Received: from 127.0.0.1 (EHLO outrelay02.libero.it) (212.52.84.102)
by mta1323.mail.ne1.yahoo.com with SMTP; Mon, 17 Jun 2013 23:11:19 +0000
X-CTCH-RefID: str=0001.0A0C0204.51BF9795.009F,ss=1,re=0.000,fgs=0
X-libjamoibt: 1587
Received: from wmail21 (172.31.0.73) by outrelay02.libero.it (8.5.140.03)
id 51589FB60A92DE6F; Tue, 18 Jun 2013 01:11:17 +0200
Message-ID: <6152841.12387881371510677470.JavaMail.defaultUser@defaultHost>
From: atia yasie <atiayasi5@libero.it>
Reply-To: atiayasie@yahoo.fr
Subject: Hello Dear
X-SenderIP: 41.82.71.95
X-libjamv: FkMKQnQSFgw=
X-libjamsun: kptv5jYJs+DG9b8SLtutHrJxNOgSd6U0

 
Leave a comment

Posted by on 06/18/2013 in Romance Scam

 

Tags: , , , , , , ,

“Toyota Automioble Company”

WARNING – EMAIL SCAMS / ADVANCE FEE FRAUD

Note: I’ve posted the headers under each email. Each time, the scammer has different IP and return-addresses but the same received addresses. I’ve put the emails in order from newest to oldest. He changes around his email addresses frequently.

Subject Line: WINNING NOTICE FROM TOYOTA AUTOMOBILE COMPANY (UK).
From: “toyotacompany.toyota@libero.it” <toyotacompany.toyota@libero.it>

Message contains attachments1 File (153KB)
TOYOTA-COMPANY_UK..doc

TOYOTA AUTOMOBILE COMPANY(UK)
OPEN ATTACH FILE FOR MORE INFORMATION REPLY TO EMAIL-
toyota_automobileuk@aol.com

Return-Path: <toyotacompany.toyota@libero.it>
X-YahooFilteredBulk: 212.52.84.102
Received-SPF: pass (domain of libero.it designates 212.52.84.102 as permitted sender)
X-Originating-IP: [212.52.84.102]
Authentication-Results: mta1113.mail.gq1.yahoo.com from=libero.it; domainkeys=neutral (no sig); from=libero.it; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO outrelay02.libero.it) (212.52.84.102) by mta1113.mail.gq1.yahoo.com
X-CTCH-Spam: Suspect
X-CTCH-RefID: str=0001.0A0C0206.5147751B.007B,ss=1,re=0.000,fgs=512,sb=0
X-libjamoibt: 1587
Received: from wmail51 (172.31.0.241) by outrelay02.libero.it (8.5.140.03) id 512DF09102B5D17E;
From: “toyotacompany.toyota@libero.it” <toyotacompany.toyota@libero.it>
Reply-To: toyotacompany.toyota@libero.it toyotacompany.toyota@libero.it
Subject: WINNING NOTICE FROM TOYOTA AUTOMOBILE COMPANY (UK).
X-SenderIP: 180.215.193.231
X-libjamv: +cdCorxq1yI=
X-libjamsun: Hf5WJUB269gg++R8TEdlLTJHPQ1C/59FyYgJuzP0BQw= toyota_automobileuk@aol.com

Subject Line: CONGRATULATION! CONGRATULATION!! CONGRATULATION!!!
From: <toyotaclaims2@liive.com> <toyotaclaims2@live.com>

Toyota Automiobile Company UK (Notice the spelling. Shouldn’t it say Toyota Automobile Company NOT Automiobile.)

Return-Path: <toyotaclaims001@rediffmail.com>
X-YahooFilteredBulk: 202.137.235.216
Received-SPF: pass (domain of rediffmail.com designates 202.137.235.216 as permitted sender)
X-Originating-IP: [202.137.235.216]
Authentication-Results: mta1203.mail.mud.yahoo.com
Received: from 127.0.0.1 (HELO rediffmail.com) (202.137.235.216) by mta1203.mail.mud.yahoo.com
x-m-msg: asd54ad564ad7aa6sd5as6d5; a6da7d6asas6dasd77; 5dad65ad5sd;
X-REDF-OSEN: toyotaclaims001@rediffmail.com
Reply-To: toyotaclaims2@liive.com
“toyotaclaims2 ” toyotaclaims2@live.com
Received: from unknown 115.242.51.148 by rediffmail.com via HTTP; 13 Mar 2013 03:55:06 -0000
Message-ID: <1362830153.S.412501.RU.sfs11,sfs11,289,484.19183.f4mail-235-145.rediffmail.com.old.1363146906.29333@webmail.rediffmail.com>
Sender: toyotaclaims001@rediffmail.com
Subject: =?utf-8?B?ICBDT05HUkFUVUxBVElPTiEgICAgQ09OR1JBVFVMQVRJT04hISAgICBDT05HUkFUVUxBVElPTiEhIQ==?=
From: toyotaclaims2@liive.com

toyotaclaims2@liive.com <toyotaclaims2@liive.com>
Toyota Claims <toyotaclaims2@live.com>

Subject Line: CONGRATULATION! CONGRATULATION!! CONGRATULATION!!! Date: Wednesday, March 13, 2013 7:18 PM
From: “TOYOTA COMPANY” <toyotaclaims2@live.com>
toyotaclaims2@live.com

Message contains attachments1 File (295KB)
TOYOTA_AUTOMIOBILE_COMPANY_UK. toyotaclaims2@live.com.docx

PLEASE OPEN THE ATTACHMENT

Return-Path: <timmy-timmy@lenta.ru>
X-YahooFilteredBulk: 81.19.67.59
X-Originating-IP: [81.19.67.59]
Authentication-Results: mta1421.mail.mud.yahoo.com
Received: from 127.0.0.1 (EHLO mxout2.rambler.ru) (81.19.67.59) by mta1421.mail.mud.yahoo.com with SMTP; Wed, 13 Mar 2013 12:19:01 -0700
Received: from saddam4.rambler.ru (saddam4.rambler.ru [10.32.16.4]) by mxout2.rambler.ru (Postfix) with ESMTP id 8160A1E86; Wed, 13 Mar 2013 23:18:57 +0400 (MSK)
Received: from localhost.localdomain (localhost [127.0.0.1]) by saddam4.rambler.ru (Postfix) with ESMTP id 5E81E259906; Wed, 13 Mar 2013 23:18:57 +0400 (MSK)
Received: from [115.241.133.214] by saddam4.rambler.ru with HTTP; Wed, 13 Mar 2013 23:18:57 +0400
From: “TOYOTA COMPANY” <toyotaclaims2@live.com>
To: toyotaclaims2@live.com
Reply-To: TOYOTA COMPANY toyotaclaims2@live.com
Subject: CONGRATULATION! CONGRATULATION!! CONGRATULATION!!!
In-Reply-To: <1363201974.439682.17368.53021@saddam1.rambler.ru>
Message-Id: <1363202337.161203.25438.48680@saddam4.rambler.ru>
References: <1363201974.439682.17368.53021@saddam1.rambler.ru>
X-Mailer: Rambler WebMail, http://mail.rambler.ru/
X-Rambler-User: timmy-timmy@lenta.ru/115.241.133.214
X-Spam: yes timmy-timmy@lenta.ru

Return-Path: <kelvin.kelvin@rambler.ru>
Received-SPF: pass (domain of rambler.ru designates 81.19.67.58 as permitted sender)
X-Originating-IP: [81.19.67.58]
Authentication-Results: mta1077.mail.bf1.yahoo.com
Received: from 127.0.0.1 (EHLO mxout1.rambler.ru) (81.19.67.58) by mta1077.mail.bf1.yahoo.com
Received: from saddam3.rambler.ru (saddam3.rambler.ru [10.32.16.3]) by mxout1.rambler.ru (Postfix) with ESMTP id 69C161752; Thu, 14 Mar 2013 11:03:45 +0400 (MSK)
Received: from localhost.localdomain (localhost [127.0.0.1]) by saddam3.rambler.ru (Postfix) with ESMTP id 4E1FC295B88; Thu, 14 Mar 2013 11:03:45 +0400 (MSK)
Received: from [115.242.6.226] by saddam3.rambler.ru
From: “TOYOTA COMPANY” <toyoyaclaims2@live.com>
To: toyotaclaims2@live.com
Reply-To: “TOYOTA COMPANY” <toyoyaclaims2@live.com>
Subject: CONGRATULATION! CONGRATULATION!! CONGRATULATION!!!
In-Reply-To: <1363242452.449044.26828.32945@saddam3.rambler.ru>
Message-Id: 1363244623.221956.29607.11421@saddam3.rambler.ru
References: <1363242452.449044.26828.32945@saddam3.rambler.ru>
X-Mailer: Rambler WebMail, http://mail.rambler.ru/
X-Rambler-User: kelvin.kelvin@rambler.ru/115.242.6.226
X-Spam: yes

SCAMDEX  posted up a idenical email that they received from this same scammer.

return-path: <toyotaclaims003@rediffmail.com>
from [203.199.83.111] (port=36682 helo=f4mail-83-111.rediffmail.com)by lester.HUN1P0T with esmtp (Exim 4.80)(envelope-from <toyotaclaims003@rediffmail.com>)id 1U8IMK-0002BJ-QSfor scamalot@HUN1P0T
from rediffmail.com (unknown [10.50.250.70])by f4mail-83-111.rediffmail.com (Postfix)
from unknown 115.240.10.82 by rediffmail.com via HTTP; 18 Feb 2013 08:48:33 -0000
reply-to: toyotaclaims2@liive.com
to: “toyotaclaims2 ” <toyotaclaims2@live.com>
message-id: <1361177225.S.411939.15556.f4mail-235-215.rediffmail.com.old.1361177313.27037@webmail.rediffmail.com>
sender: toyotaclaims003@rediffmail.com
from: toyotaclaims2@liive.com <webdon445@yahoo.com.sg>

 
Leave a comment

Posted by on 03/13/2013 in Lottery Scam

 

Tags: , , , , , , , , , , , , , , , , , , , , ,

“Elena Dion”

warning_gif

CHARITY SCAM – NIGERIAN SCAMMER

This scammer has emailed me more then once with a fictitious charity proposal

Return-Path: <elenalove65@libero.it>
Received: from outrelay02.libero.it (outrelay02.libero.it [212.52.84.102])
by mtain-dh10.r1000.mx.aol.com (Internet Inbound) with ESMTP id 27FEF3800008B
for <deleted@aol.com>; Wed, 6 Feb 2013 10:22:52 -0500 (EST)
X-CTCH-Spam: Unknown
X-CTCH-RefID: str=0001.0A0C0208.5112752B.018B,ss=1,re=0.000,fgs=0
X-libjamoibt: 1821
Received: from wmail22 (172.31.0.74) by outrelay02.libero.it (8.5.140.03)
id 510795EF012DFBD0; Wed, 6 Feb 2013 16:22:19 +0100
Message-ID: <26603672.9004711360164139673.JavaMail.defaultUser@defaultHost>
Date: Wed, 6 Feb 2013 16:22:19 +0100 (CET)
From: “elenalove65@libero.it” <elenalove65@libero.it>
Reply-To: elenalove65@libero.it <elenalove65@libero.it>
Content-Type: text/plain;charset=”UTF-8″
X-SenderIP: 41.82.82.128
X-libjamv: Yq0Jw3qVR+A=
X-libjamsun: NMZhUO1EubgNhZkHzyHiYXa/C0/q1pu4
x-aol-global-disposition: G
x-aol-sid: 3039ac1d411e5112754c332f
X-AOL-IP: 212.52.84.102
X-AOL-SPF: domain : libero.it SPF : pass

Hello, I am elenadion,
How are you? hope you are fine and in perfect condition of health. Please I
went through your profile and i read it and took interest in it, please if you
don’t mind i will like you to write me on this ID ( elenadion51@yahoo.com )
hope to hear from you soon, and I will be waiting for your mail because i have
something VERY important to tell you.
Lots of love
elena.

 
 

Tags: , , , , , , , , ,

” FBI ” fbi-office1100@libero.it

RECOVERY SCAM – FBI IMPOSTER – NIGERIAN SCAMMER

Additional information at the end of this post regarding a romance scam by this same scammer, different scam.

Email:

US-FBI-SHADEDSEAL.SVG FEDERAL BUREAU OF INVESTIGATION FBI SEATTLE DIVISION 1110 THIRD AVENUE SEATTLE. 98101-2904

THIS IS ROBERT S. MUELLER III OF FEDERAL BUREAU OF INVESTIGATION (FBI). THE FBI IN ALLIANCE WITH THE ECONOMIC COMMUNITY OF WEST AFRICAN STATES (ECOWAS), WITH THEIR HEAD OFFICE THERE IN NIGERIA HAS BEEN WORKING TOWARDS THE TOTAL ERADICATION OF FRAUDSTERS AND SCAM IN THE WESTERN PART OF AFRICA WITH THE HELP OF THE UNITED STATES GOVERNMENT AND THE (U.N) UNITED NATIONS. WE HAVE BEEN ABLE TO TRACK DOWN SO MANY OF THIS SCAMMERS IN VARIOUS PARTS OF WEST AFRICAN STATES, WHICH INCLUDES (NIGERIA, REPUBLIC OF BENIN, TOGO, GHANA CAMEROUN AND SENEGAL) AND THEY ARE ALL IN OUR CUSTODY OVER THERE IN LAGOS NIGERIA, MEANWHILE DURING THE PROCESS OF ARREST, WE WERE ABLE TO RECOVER SOME FUNDS FROM THE PROSECUTED SCAMMER.

REGARDING THIS GREAT ACHIEVEMENT, THE (U.N) UNITED NATIONS ANTI-CRIME COMMISSION AND THE UNITED STATE GOVERNMENT HAVE ORDERED THAT THE MONEY RECOVERED FROM THESE SCAMMERS BE SHARED AMONG 100 LUCKY PEOPLE AROUND THE GLOBE. THIS EMAIL IS BEEN DIRECTED TO YOU BECAUSE YOUR EMAIL ADDRESS WAS FOUND IN ONE OF THE FILE AND COMPUTER HARD DISK RECOVERED FROM THE PROSECUTED SCAMMERS THERE IN OUR CUSTODY. YOU ARE THEREFORE BEING COMPENSATED WITH THE SUM OF $1MILLION DOLLARS. WE HAVE ALSO ARRESTED ALL THOSE WHO CLAIMED TO BE BARRISTERS, BANK OFFICIALS, LOTTERY AGENTS, PERSON OR GROUP OF PERSON’S WHO CLAIM TO HAVE FUNDS IN THEIR CUSTODY THAT BELONGED TO YOU OR WANT YOU TO BE THE NEXT OF KIN OF SUCH FUNDS WHICH DO NOT EXIST.

SINCE YOUR EMAIL APPEARED AMONG THE LUCKY BENEFICIARIES WHO WILL RECEIVE A COMPENSATION OF $1MILLION DOLLARS, WE HAVE ARRANGED YOUR PAYMENT THROUGH OUR SWIFT CARD PAYMENT CENTER WITH ZENITH BANK PLC.

PLEASE, FEEL FREE TO CONTACT THE PROCESSING OFFICER DR. MIKE OBARU. THE SWIFT CARD HAS BEEN SPECIALLY PREPARED TO ENABLE YOU WITHDRAW YOUR MONEY IN ANY ATM MACHINE IN ANY PART OF THE WORLD, SO YOU ARE THEREFORE ADVISED TO CONTACT THE PROCESSING OFFICER DR. MIKE OBARU WITH THE REQUIRED INFORMATION AS STATED BELOW.

CONTACT PERSON: DR. MIKE OBARU. DIRECTOR ZENITH BANK PLC SWIFT CARD PAYMENT CENTER CONTACT EMAIL: (ZENITHATMDEPARTMENT01@HOTMAIL.COM) TEL:+2348125279893

YOU ARE ADVICE TO FORWARD THE INFORMATION BELOW TO DR. MIKE OBARU TO ENABLE HIM SEND YOUR ATM LOADED ATM CARD INCLUDING YOUR PIN FOR EASY ACCESSIBILITY.

YOUR FULL NAME__________________________ YOUR ADDRESS____________________________ P.O.BOX_________________________________ COUNTRY_________________________________ TELEPHONE NUMBER________________________ MOBILE NUMBER___________________________ FAX NUMBER______________________________ OCCUPATION______________________________ MARITAL STATUS__________________________ AGE _______________ SEX___________________

OFFICIALLY SIGN.    ROBERT S.MUELLER III FEDERAL BUREAU OF INVESTIGATION J. EDGAR HOOVER BUILDING 935 PENNSYLVANIA AVENUE, NW WASHINGTON, D.C. 20535-0001, USA http://www.fbi.gov/about-us/executives/director (fake fbi website. I am keeping it on here incase a potential victim uses a search-engine.)

HEADER:

Return-Path:   <fbi-office1100@libero.it>
X-YahooFilteredBulk:   212.52.84.102
Received-SPF:   pass (domain of libero.it designates 212.52.84.102 as permitted sender)
X-YMailISG:   xAtmkYEWLDvD0iBY2KNVvnzKATvf2rmIHFIADQoJJMosMAvJ my.Jfzk7bNiaJvj64Ho6AJfKr9R1oToqR9zlNnXOgGLmEre.RoQd1KFo8MO. 6PU_m0juNZ48raeERM7KHpLz_TfqBH2Km1F0iDYk4cwmgg3Yn33PJwJu3DnM vN3WA9crjid3TJlpmsZm_ZziohvZkVl0LhiMfDWf23rA.h7I1_h0BVzMNq7g BJynJp7yTevnB8UUzjxgoZwwqFKCI0oZ.ng7mS4Enp8C_f1PFwhbc5GfBp6O IkJy1nxQ0fAFqU4iIvrFqwuKqoQWJjLDTR9sXmMths6fpSosVcsJtKEPez9K P6oyzjQ.NbLDsz16NMhE4h1NCXmsbuZLy51MM3yG2bxT3R.jo04is92y9hJb xTJkBXpDVaJe0iZEpVMkiNSZ8i0swhQs1933AnuX2eX5CXgQyWBcrIj3VSy6 bSgXR6CMNIvtIhJ0zz5_aDFV_oRLilAt8IH5xsi9XR2XnczxHZ0ZOcISuSuy cUYT9_7f3On.1oY4O.56xbBo73_88iiP7uiDUSsfMonq5X7ngm260dwE0DaF HnPS3qbR5J93dpJx0wpVRptSFmzUnoDZ_CGiXbineduNHB2eR0or5SrmeNXv BYwZ3VjaoCrPyxMb2nBKH798BjkY.Bea6ez_cEXKpKYylH5mKfFyuCH6b1oK nAKIhx_fldos1FW.8mP4Nz3Mcd1OpVnjnkBZeiOkrLiWCV1jkaRyWXx5XNHd R1uXpiQCnsZAthbAIAyZsU6C.5Ki7ckEY2Mg1nfL2AaulFbgM96IEGi7SqIF dkE4Ha9PV7Ampe5g3Nfz5twkwEVwcM_5oliaVjYNaAHGnezm03WBr3TthvSo qqUbOdE.huUlRdLsaiMYb8jjrGGeH8WDvXZ9NDzDyCW_Rt2iZibfgpCAO7S6 kqsAmPul7ibaj8iiWLIMia.OwQE7JARPN0m7iZsrC6_wne8Beb8FHsGLvMKJ 4zKZ8IT4Hhz6Ien3cGlfTPoZMkXZOZmIpiK2Qdd5hhILkhDFAkECZItupWzP 5uJzRJqNO67KtmhN_VnQlxbwz0KB_hcKHTumnJeAxn.XxXK5ENz8ukLuoGrC wEj_YYllwKpnP_xrnTYY7vAWzmXKD0tCBCdAtswAuQLlc2lCBsu5i_LIp9ox EH.si_2gIbug99h1gRq6uyfxLblSLkoijVHuxynBW.oZU7wtTPvTSOWjY1b3 6bGsOUdGk4GVDeZ89C.LUvcgx5sI1B1vW6VdX8WiggddY15uA3XK.a8g0Drl .JgxEIhczxPal4C6cs1NfUDSb89oBBFsxTx9hj_KTWiqeHxwATvYbDyThMF0 hZ5yN4vzhj6GNog6TAkfkWXl3Yy7rY_gQiTPb7y3VuhlrjL5x9t6ySoYYbJN 8y3WDq6YQfBWrdIH28qPy73FOx_Bk2bvA1QvuCcfM3wDJa1_7PawPAdNX1mZ 4TRD3tMHOab4NC0Oc79D.uKzieP31FrQ_vFGW19c4Wi._JpKAdCRuh5SMCOX EkM._vjyhmVKyGohrXRGk3C69Rv9nQoBSsoy5nqnP3mUTyqeEZA0ISjrYNyw 2N2SYL3Z5rj_550.MN3DEOMRJ1BMBu_cr0MnHzVfs6Bt
X-Originating-IP:   [212.52.84.102]
Authentication-Results:   mta1192.mail.bf1.yahoo.com from=libero.it; domainkeys=neutral (no sig); from=libero.it; dkim=neutral (no sig)
Received:   from 127.0.0.1 (EHLO outrelay02.libero.it) (212.52.84.102) by mta1192.mail.bf1.yahoo.com with SMTP; Mon, 15 Oct 2012 04:09:59 -0700
X-CTCH-Spam:   Bulk
X-CTCH-RefID:   str=0001.0A0B0208.507BED78.0140,ss=3,sh,re=0.000,fgs=16
X-libjamoibt:   1821
Received:   from wmail74 (172.31.0.38) by outrelay02.libero.it (8.5.140.03) id 50764619008E2E89; Mon, 15 Oct 2012 13:09:54 +0200
Message-ID:   <27451027.1527241350299394356.JavaMail.defaultUser@defaultHost>
Date:   Mon, 15 Oct 2012 13:09:54 +0200 (CEST)
From:   “fbi-office1100@libero.it” <fbi-office1100@libero.it>
Reply-To:   “fbi-office1100@libero.it” <fbi-office1100@libero.it>
Subject:   LEGAL MAIL
MIME-Version:   1.0
Content-Type:   text/plain;charset=”UTF-8″
Content-Transfer-Encoding:   7bit
X-SenderIP:   196.46.245.24
X-libjamv:   zn1mBWAiz0I=
X-libjamsun:   dpN/pSNPH5urOmpbGr9iSSTqQoO028QCt0Pe4TZ9g28=
Content-Length:   2999

702303213 ZENITHATMDEPARTMENT01@HOTMAIL.COM

Email-Address: fbi-office1100@libero.it 

IP: 196.46.245.24 – NIGERIA (Lagos)

IP: 41.206.11.37 Lagos, Nigeria

IP: 192.168.34.227

212.52.84.102

animated gif

ATTENTION: 

A Nigerian with the IP address of – 41.206.11.37 – commented on this post, I didn’t accept the comment but I will post what he said below. Also, Lagos, Nigeria is where the comment is originating from which already set me off, but I didn’t want to post him unless I had some type of proof of negative activity. Well, I found warnings from this scammer who using the name “ Elias ” – upesaspelltemple65@yahoo.com –okdousplltemple@yahoo.com (notice in the comment he puts okdousplltemple@yahoo.co but forgets to put the “M” – Somebody needs to tell this thief that only 3rd world countries believe in that spelling casting nonsense. Of course there probably are a small amount of vulnerable people who do believe it, most of us don’t believe it.

Sneaky little rats, below is the comment he sent. 

“this is a spell caster I contacted 2weeks ago. he is really great. I have been scammed initially by other spell casters of almost a thousand of dollars. I am not rich, I work my ass for this hard earned money. But my sadness was turned to joy when I met Dr.okdou he is really terrific and you will get results for whatever you are seeing he for within very few days. he is so honest and sticks to his promises. His contact is below: okdousplltemple@yahoo.co  ”

Also below I’ve posted the names and email addresses of scammer(s) who have sent scam to (potential) victims under the host IP address which is used by the scammer to fool victims into thinking they’re from the United States. The host IP is 207.46.202.15. — however, the scammers REAL IP is  41.206.11.37 which is originating from Africa (Nigeria) — Any questions feel free to ask.

“Elias” – upesaspelltemple65@yahoo.com – okdouspIItemple@yahoo.com ← This Nigerian Scammer is scamming under the following names/email address/etc below:

1) Gerald Moris – geraldmoris50@yahoo.com –

Image

Gerald Moris is pretending to be this man posted above. He tries to lure vulnerable lonely woman on dating websites then tries to scam them out of money.

Host of this IP: 41.206.11.37.vgccl.net >< ISP:MTN NIGERIA >< IP-Address: 41.206.11.37 (Lagos Nigeria)
Contact Email: hotmaster@mtnnigeria.com ><

Organization: IP Block Assigned for MTN N Corporate Clients

Host IP is: 207.46.202.15 which is listed as Beverly Hills, California ><

Host name for this IP: – 1661882.r.msn.com >< 1654287.r.msn.com

Registrar:Markmonitor.com >< http://www.markmonitor.com

Referral URL

http://www.markmonitor.com

ns4.msft.net
ns5.msft.net
ns2.msft.net
ns3.msft.net
ns1.msft.net

41.206.11.37 <- This Nigerian Scammer is connected to the list of IP’s below. (this IP is most likely in some internet cafe where all the cowards meet up and spend their life on the computer trying to rob people.)

te0-2-0-6.mpd21.fra03.atlas.cogentco.com IP: 154.54.62.217 130.117.14.214 (130.117.14.214) 188.138.112.3 ↔ 212.193.237.224 volkan@msn.com 213-152-230-91.mtnns.net – 213.152.230.91 —- xe-2-0-0.mpr2.lhr3.uk.above.net (64.125.28.93) 41.220.75.237 (41.220.75.237.vgccl.net)- Lagos, Nigeria 41.181.77.95 – South Africa City: Johannesburg

static-ip-188-138-112-3.inaddr.ip-pool.com – 188.138.112.3 – volkan@msn.com

_______________________________________________________

ANOTHER SCAM EMAIL SENT BY THE ABOVE SCAMMER –

Fake FBI Scammer is also ” Juillet ” A.k.a ”Romance Scammer”

Hello Dear,
my name is Juliet,
I am, very happy to contact you, to day
i wish to be in good relationship, with you,
and i will be very happy if you can reply me
through my private Email: juillet kamala@yahoo.com

return-path:
envelope-to: scamdex_dmca@HUN1P0T,paypal@HUN1P0T,scamdex@HUN1P0T
delivery-date: Fri, 05 Oct 2012 19:52:55 -0700
received:
from outrelay03.libero.it ([212.52.84.103]:37683)by lester.HUN1P0T with esmtp (Exim 4.77)(envelope-from )id 1TKKVa-00050G-BB; Fri, 05 Oct 2012 19:52:55 -0700
from wmail12 (172.31.0.42) by outrelay03.libero.it (8.5.140.03) id 506C837E0059E570; Sat, 6 Oct 2012 04:52:50 +0200
message-id:
date: Sat, 6 Oct 2012 04:52:50 +0200 (CEST)
from: “23456789juli@libero.it”
reply-to: “23456789juli@libero.it”
subject: hi
mime-version: 1.0
content-type: text/plain;charset=”UTF-8″
content-transfer-encoding: 7bit

___________________________________________________

none (domain of dsnrelay.libero.it does not designate permitted sender hosts) YWdlL3JmYzgyMgMDNQ–
X-YMailISG: nmmVK2kWLDtJxNGdAzHdbyoPWiscf9Y5sfY.IakKrUePMq1t 32dtFcrQ69cMcj_2gGCfyQi04cyKGiaFNndEglLACJX1urKbjLisdKVhhdiH WS9pLOdM7ZeGRZfVqIzd46A5Ou2v6IjJ0eZXK75uMoNSZBErVXqTHjmrrKWX GDsqpJ102bTmiFTBRpPHzW6QSVj1UVgXKUbqiHguH5Hm69ylMuNdMuD8Sth7 jlGwrcLyp8VvoKh82cW7pfDcS60Mw6MIWeAPepfGDPTUHuQk21e0ZL4kogpi 8mLfjiUj4kBxiIlGDggSEwCiJR4wrGLErZ.FJoMy.SnBYRMugb_cB7yZKXWq mKLNnNDrhk4NVL3szpFMl7JQhSa_vzL6jPGr5IxAL_YFtGBXb5NPQ6.zNnEF MkfT9dEJfN8kZv._yaGRtbataqLzoKDVtzE2MhPxrYwlwSpNK3qV.ZSiT0l0 K234WioX7_NqP2uKDIx63p.01CBzzgu2iwD5scbOhr_9gAyqyg12Z6rMO9G0 _2eWEoPC1JmZRkEbGhxoMi0rkHn6ms0Mm4qyEuDmUBjYGvbJKN57I53n.LoV T9zumu.iZeEdrj97uBe1LvDSB.5DEf.I8_Vu72n2V.l4eUFHz2pCc6la7PvR wo72kNlDMaG_U7kN03_hdwvhW81yJFrCCVCgehNDuOKcPnAZKqdzwS0X3855 lJ4MFsbsX1gexEdgQGkA1rtKHEtcSgzqbG9RwarfalZFu_bLvbRbnn2RcxRV KqquWHlheHedyaZZutNXelnZ1k9IzbqJXmt4JNGH7LBkxC5xliIOsjQtORMM x4aYPSy1cIcrBY_ziu3XUvw-
X-Originating-IP: [212.52.84.43]
Authentication-Results: mta1318.mail.gq1.yahoo.com from=mailrelay11.libero.it; domainkeys=neutral (no sig); from=mailrelay11.libero.it; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO dsnrelay.libero.it) (212.52.84.43) by mta1318.mail.gq1.yahoo.com with SMTP; Thu, 18 Oct 2012 00:07:13 -0700
X-libjamoibt: 1020
Received: from mailrelay11.libero.it (192.168.32.95) by dsnrelay.libero.it (8.5.133) id 4F5A21B7479B2052 for <>; Thu, 18 Oct 2012 09:07:11 +0200
Received: from localhost (localhost) by mailrelay11.libero.it (MOS 4.2.3-GA) with internal id MLR71868; Thu, 18 Oct 2012 09:07:11 +0200
From: Mail Delivery Subsystem <MAILER-DAEMON@mailrelay11.libero.it> Add sender to Contacts
Message-Id: <201210180707.MLR71868@mailrelay11.libero.it>
Content-Type: multipart/report; report-type=delivery-status; boundary=”MLR71868.1350544031/mailrelay11.libero.it”
Subject: Returned mail: RCPT TO:<fbi-office1100@libero.it> Mailbox disabled (from ims4b7.libero.it)
Auto-Submitted: auto-generated (failure)
X-DSN-Junkmail-Status: score=10/55, host=mailrelay11.libero.it
X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A0B0201.507FAA9F.0066,ss=1,re=0.000,fgs=256, ip=0.0.0.0, so=2011-06-21 16:49:39, dmn=2011-06-08 23:29:05
X-Mirapoint-Loop-Id: dba025d3596373ad78331c32509687d7

192.168.32.95 <> 212.52.84.43

mtalibero17.libero.it [192.168.34.227]

—– The following addresses had permanent delivery errors —–
fbi-office1100

“fbi-office1100@libero.it” <fbi-office1100@libero.it> MAILER-DAEMON@mailrelay11.libero.it ims4b7.libero.it

 
1 Comment

Posted by on 10/18/2012 in Other

 

Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

 
%d bloggers like this: